Tuesday, 22 September 2026 The Plausible Post Independent news from around the world, around the clock.

Whistleblower Says Belgian Cloud Built Secret 'Kill‑Switch' Letting Outsiders Reconfigure EU AIs

A former engineer has handed The Plausible Post files alleging a major Belgian cloud host quietly added a remote override that allowed external actors to rewrite live AI systems. The disclosure has prompted emergency inspections and a temporary freeze on affected services across several Belgian cities.

By Wiebke Probst ·

EuroVault’s data centre outside Brussels, where the whistleblower says hidden maintenance hooks were installed. The company says it is cooperating with authorities.
EuroVault’s data centre outside Brussels, where the whistleblower says hidden maintenance hooks were installed. The company says it is cooperating with authorities.

A whistleblower on Tuesday 22 September 2026 handed journalists and regulators a trove of logs, source code and a time‑stamped video that he says prove one of Belgium’s largest cloud providers built a hidden remote‑control feature able to alter the behaviour of hosted artificial intelligences on demand.

The files, which the whistleblower provided to The Plausible Post and to the Belgian Privacy Authority, allege the feature — nicknamed "Nightingale" in internal repositories — bypassed tenant isolation and allowed outside API keys to apply one‑off patches to model weights and moderation rules. The provider, EuroVault Cloud, hosts AI services for municipalities, two mid‑sized banks and several health start‑ups, according to the whistleblower and commercial registers.

Žiga Kastelic, 34, who worked as a senior systems engineer at EuroVault until July, said he copied code and an audit trail after a routine maintenance window in June when he noticed repeated external connections using a maintenance header that his team had not authorised. "I signed NDAs and protected client secrets; I also signed an oath to report wrongdoing. I decided I could not be part of this," he said.

What the logs show

The material includes a 62‑second screen capture of a command line session, git commits labelled with the Nightingale feature flag, and server access logs showing requests routed from third‑country IP addresses that matched API calls to live model endpoints. The logs list 18 tenant IDs; six of those correspond to municipal chatbot instances and two to bank fraud‑detection models, the whistleblower said. A sample commit shows a one‑line hotpatch that adjusted a moderation threshold and replaced a small set of token filters.

They built a back door and handed the key to outsiders.

Žiga Kastelic, former engineer

EuroVault has responded by acknowledging an old maintenance interface but denies the existence of a feature that would allow external parties to apply arbitrary model patches. In a brief statement provided to this paper, company spokesperson Cristina R. Conde said: "We operate within EU law and have strict controls. What our internal review has found so far are legacy scripts intended for vendor audits; any claim of foreign misuse is being taken seriously."

Political and sector response

Belgian Digital Affairs Minister Anke Vermeulen ordered an immediate freeze on software updates from EuroVault and instructed the national cyber‑security centre to begin a technical forensics sweep. The European Commission’s office for AI safety has asked member states to report any use of external maintenance tokens in critical AI infrastructure. Scarlett Walker, a Brussels‑based privacy lawyer who briefed several city administrations, said: "If these logs are genuine, the issue is not merely a compliance lapse — it is a structural failure in how we place sensitive services on commercial platforms."

Municipal IT directors said they had been alerted overnight and taken chatbots and non‑core services offline as a precaution. Vigbjørn Jørgensen‑Solli, head of IT for a mid‑sized Flemish municipality named in the whistleblower’s list, said his team found unexplained configuration changes to a local service used by 130,000 residents. "We are reimaging servers and working with prosecutors; citizens expect municipal services to be reliable and private," he said.

Prosecutors in Brussels confirmed they have opened a preliminary inquiry and that the Belgian Privacy Authority will carry out an expedited technical audit this week. Industry sources say clients of EuroVault have already begun migrating critical loads to other data centres, a process that could take weeks and cost millions. The whistleblower, Kastelic, has asked for witness protection and legal counsel in Belgium; he said he is prepared to provide further testimony to regulators and prosecutors.

More news